6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

OWASP CRS

Open source

The OWASP Core Rule Set is a collection of generic attack detection rules for ModSecurity, Coraza and other compatible web application firewalls.

coreruleset.org
OWASP CRS homepage screenshot
GitHub stars
3.3k
Last commit
today
Repository age
6 years
Version
v4.29.0
Licence
Apache-2.0
Self-hosted
Yes

About OWASP CRS

The OWASP Core Rule Set, or CRS, is a set of generic attack detection rules meant to be loaded into a web application firewall. It works with OWASP ModSecurity, OWASP Coraza and other compatible engines rather than running as a standalone application. The rules are written to protect web applications against a broad range of attacks while keeping false alerts to a minimum.

Coverage is aimed at threats such as those in the OWASP Top Ten. The project invites reports of false positives, false negatives and evasions through GitHub issues, and asks for the installed version and relevant audit log portions to help reproduce each case. Discussion takes place in a Google Group and the coreruleset channel on OWASP Slack, and the project website links to installation and configuration resources.

The ruleset is released under the Apache-2.0 license, with copyright held by Trustwave and contributors up to 2020 and by the CRS project afterward. The latest release listed is v4.29.0. Because it is a ruleset, it suits teams already operating a compatible WAF who want maintained, community-reviewed detection logic.

Key features

  • Generic attack detection rules for web applications
  • Compatible with ModSecurity and Coraza
  • Targets the OWASP Top Ten threat categories
  • Tuned to limit false positives
  • Community channels for reporting evasions

Good fit for

  • β†’Adding baseline protection to a WAF
  • β†’Hardening public-facing web applications
Built with
Python
Tags
waf
owasp
security
ruleset
modsecurity
coraza
web-security
open-source

Open-source alternatives to OWASP CRS

See all

SaaS alternatives to OWASP CRS

See all